Перейти к содержимому
Noroxi

Записи pluck-cms

46 опубликованных записей вендора pluck-cms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
12
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

46 записей
  • CVE-2023-50564
    44В плане

    An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary

    ВысокаяCVSS 8,8Proof of conceptEPSS 29 %

    pluck-cms · pluck14 дек. 2023 г.

  • CVE-2018-11736
    42В плане

    An issue was discovered in Pluck before 4.7.7-dev2.

    КритическаяCVSS 9,8Proof of conceptEPSS 9 %

    pluck-cms · pluck5 июн. 2018 г.

  • CVE-2020-20951
    40В плане

    In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    pluck-cms · pluck18 мая 2021 г.

  • CVE-2019-11344
    40В плане

    data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    pluck-cms · pluck19 апр. 2019 г.

  • CVE-2014-8708
    40В плане

    Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    pluck-cms · pluck17 мар. 2017 г.

  • CVE-2021-31746
    40В плане

    Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    pluck-cms · pluck10 дек. 2021 г.

  • CVE-2018-11331
    40В плане

    An issue was discovered in Pluck before 4.7.6.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    pluck-cms · pluck21 мая 2018 г.

  • CVE-2019-1010062
    40В плане

    PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    pluck-cms · pluckcms16 июл. 2019 г.

  • CVE-2022-26965
    39Наблюдать

    In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

    ВысокаяCVSS 7,2Proof of conceptEPSS 36 %

    pluck-cms · pluck18 мар. 2022 г.

  • CVE-2020-20718
    39Наблюдать

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to t

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pluck-cms · pluckcms20 июн. 2023 г.

  • CVE-2024-43042
    39Наблюдать

    Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pluck-cms · pluck16 авг. 2024 г.

  • CVE-2020-29607
    38Наблюдать

    A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through

    ВысокаяCVSS 7,2Proof of conceptEPSS 33 %

    pluck-cms · pluck16 дек. 2020 г.

  • CVE-2020-21564
    36Наблюдать

    An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    pluck-cms · pluck30 сент. 2020 г.

  • CVE-2020-18198
    35Наблюдать

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the c

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pluck-cms · pluck17 мая 2021 г.

  • CVE-2020-18195
    35Наблюдать

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via th

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pluck-cms · pluck17 мая 2021 г.

  • CVE-2022-27432
    35Наблюдать

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featur

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pluck-cms · pluck29 мар. 2022 г.

  • CVE-2018-16634
    35Наблюдать

    Pluck v4.7.7 allows CSRF via admin.php?action=settings.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pluck-cms · pluck4 дек. 2018 г.

  • CVE-2021-27984
    33Наблюдать

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %

    pluck-cms · pluck10 дек. 2021 г.

  • CVE-2009-1765
    32Наблюдать

    Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute

    СредняяCVSS 6,8Proof of conceptEPSS 15 %

    pluck-cms · pluck22 мая 2009 г.

  • CVE-2020-20969
    30Наблюдать

    File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

    ВысокаяCVSS 7,2Proof of conceptEPSS 6 %

    pluck-cms · pluck20 июн. 2023 г.

  • CVE-2021-31745
    30Наблюдать

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    pluck-cms · pluck10 дек. 2021 г.

  • CVE-2019-9050
    29Наблюдать

    An issue was discovered in Pluck 4.7.9-dev1.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    pluck-cms · pluck23 февр. 2019 г.

  • CVE-2008-6253
    28Наблюдать

    Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers t

    СредняяCVSS 6,8Proof of conceptEPSS 5 %

    pluck-cms · pluck24 февр. 2009 г.

  • CVE-2008-6842
    28Наблюдать

    Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute a

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    pluck-cms · pluck2 июл. 2009 г.

  • CVE-2023-25828
    28Наблюдать

    Authenticate Remote Code Execution in Pluck CMS

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    pluck-cms · pluck27 мар. 2023 г.